Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
# Add to your Claude Code skills
git clone https://github.com/CyberStrikeus/CyberStrikeLast scanned: 5/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-30T15:06:22.697Z",
"npmAuditRan": false,
"pipAuditRan": true
}CyberStrike is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by CyberStrikeus. Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team. It has 1,627 GitHub stars.
Yes. CyberStrike passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/CyberStrikeus/CyberStrike" and add it to your Claude Code skills directory (see the Installation section above).
CyberStrike is primarily written in TypeScript. It is open-source under CyberStrikeus on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh CyberStrike against similar tools.
No comments yet. Be the first to share your thoughts!
npm i -g @cyberstrike-io/cyberstrike@latest && cyberstrike
That's it. CyberStrike launches a TUI in your terminal, asks for your LLM provider and API key on first run, and you're ready to go. Tell it what to test — it handles reconnaissance, vulnerability discovery, exploitation, and reporting autonomously.
Already have a Claude Code or OpenAI subscription? CyberStrike's intelligence layer sits on top of your existing AI subscription. No separate API costs — your current plan powers an entire pentest toolkit.
Explore the full documentation at docs.cyberstrike.io or visit cyberstrike.io for demos and guides.
CyberStrike isn't just a wrapper around an LLM. It's an intelligence layer that transforms any AI model into an offensive security specialist.
How it works: When you connect your LLM provider, CyberStrike injects domain-specific context — OWASP testing methodology, vulnerability patterns, attack chain reasoning, and tool orchestration logic — into every interaction. The model doesn't need to know security; CyberStrike teaches it.
What the intelligence layer provides:
150+ AI providers and 5,300+ models supported out of the box:
CyberStrike integrates with the entire AI ecosystem through 23 bundled SDK providers and 150+ providers via the models.dev catalog. Here are the core integrations:
| Provider | Models | Notes |
|---|---|---|
| Anthropic | Claude 4.5, Claude 4 | Best performance with extended thinking |
| OpenAI | GPT-5, GPT-4.1, o3, o4 | Full tool-use + reasoning support |
| Gemini 2.5 Pro/Flash | Long context for large codebases | |
| Amazon Bedrock | All Bedrock models | IAM auth, no API keys needed |
| Azure OpenAI | All Azure-hosted models | Enterprise deployments |
| Google Vertex AI | Gemini + Claude on GCP | Regional endpoints (EU/US) |
| GitHub Copilot | GPT-5, Claude, Gemini | Use your existing Copilot subscription |
| xAI | Grok 3, Grok 3 Mini | Real-time data access |
| Groq | LLaMA, Mixtral | Ultra-fast inference |
| Mistral | Mistral Large, Codestral | European data residency |
| DeepSeek | DeepSeek V3, R1 | Cost-effective alternative |
| Cerebras | LLaMA on Cerebras | Fastest inference available |
| Cohere | Command R+ | RAG-optimized models |
| OpenRouter | 300+ models | Single API, any model |
| Together AI | Open-source models | Fine-tuning support |
| DeepInfra | Open-source models | Pay-per-token, no GPU needed |
| Perplexity | Sonar models | Search-augmented generation |
| Alibaba Cloud | Qwen, Kimi, DashScope | Chinese model ecosystem |
| Cloudflare AI Gateway | Any provider via gateway | Caching, rate limiting, analytics |
| Ollama | Any GGUF model | Fully offline, local-only |
| LM Studio | Any local model | Desktop GUI + API server |
| vLLM | Any HuggingFace model | Self-hosted, GPU-optimized |
| Any OpenAI-compatible | — | Custom endpoints welcome |
Air-gapped environments? Run CyberStrike entirely offline with Ollama or LM Studio. No data leaves your machine — ever.
Specialized Security Agents, Not Generic Chat
CyberStrike ships with 13+ agents purpose-built for security domains. Each agent carries domain-specific methodology, tool knowledge, and testing patterns. The web-application agent follows OWASP WSTG. The cloud-security agent knows CIS benchmarks. The mobile agent uses Frida and follows MASTG/MASVS. They don't guess — they follow proven offensive security frameworks.
Intelligence Layer, Not Just an LLM Wrapper
Most AI security tools are thin wrappers that send your prompt to an API. CyberStrike's intelligence layer normalizes outputs across 150+ providers and 5,300+ models, guards context between test phases, auto-detects your provider configuration, and orchestrates multi-step attack chains. The result: consistent, methodology-driven pentesting regardless of which model you use.
150+ Providers, Zero Lock-in
Anthropic, OpenAI, Google, Amazon Bedrock, Azure, Groq, Mistral, xAI, DeepSeek, Cerebras, Cohere, OpenRouter, Together AI, GitHub Copilot — or run fully offline with Ollama and LM Studio. 150+ providers, 5,300+ models. You choose the model. You own the results. As AI models get better and cheaper, CyberStrike gets better with them. Switch providers in seconds without reconfiguring anything.
Remote Tool Execution with Bolt
Your security tools don't have to run on your laptop. Deploy Bolt on one or many remote servers, pair with Ed25519 keys, and control everything from your local terminal. One CyberStrike instance can orchestrate dozens of Bolt servers — each with its own toolkit, network position, and attack surface access.
Switch between agents with Tab. Each one is a domain specialist.
| Agent | Focus | What It Does |
|---|---|---|
| cyberstrike | Ge |